CVE-2002-1015 - CVE House
Back to Database
Status published High CVE-2002-1015

RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505,...

Vulnerability Description

RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by Internet Explorer or other Microsoft-based web readers.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2002-1015

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

realnetworks

View all reports →

Affected Software

realjukebox 2, realjukebox 2 plus, realone player
Vulnerable Versions:
1.0.2.340, 1.0.2.379, 6.0.10.505

Timeline

Official Publish: April 2nd, 2003
Last Modified: August 8th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.